Galactic Research: Articles & Insights
Threat Thursday: August 20th, 2026

Welcome to Threat Thursday, Galactic’s weekly threat intelligence roundup. Every Thursday, we cover the cybersecurity stories that matter most for protecting organizations from emerging threats, and we break each one down into what happened, what it could mean for your ...
AI Security
Part 2: The Security Controls Behind a Safe AI Deployment

From the Map to the Hike: The Four Controls and the Client Conversations Behind Them This is Part 2 in a series that covers your AI enablement plan. Part 1 is here if you want the full map. The Little ...
Ten of Eleven AI Coding Agents Failed a Decades-Old Attack

What GuardFall Tells Us About Where AI Security Controls Need to Live Picture a security guard stationed at the entrance of a building. Their job is to check IDs. They're good at it, fast and consistent, and the building's occupants ...
Perfect AI Guardrails Are Impossible. That's Not an Excuse for Ignoring Them.

What a NIST Mathematician Proved, Why the Internet Got it Wrong, and What Your AI Security Program Should Look Like Years ago, running an MSSP, I had a vendor pitch us a next-gen firewall on a single promise: one hundred ...
Threat Intelligence
Threat Thursday: August 20th, 2026

Welcome to Threat Thursday, Galactic’s weekly threat intelligence roundup. Every Thursday, we cover the cybersecurity stories that matter most for protecting organizations from emerging threats, and we break each one down into what happened, what it could mean for your ...
Threat Thursday: August 13th, 2026

Welcome to Threat Thursday, Galactic’s weekly threat intelligence roundup. Every Thursday, we cover the cybersecurity stories that matter most for protecting organizations from emerging threats, and we break each one down into what happened, what it could mean for your ...
Threat Thursday: August 6th, 2026

Welcome to Threat Thursday, Galactic’s weekly threat intelligence roundup. Every Thursday, we cover the cybersecurity stories that matter most for protecting organizations from emerging threats, and we break each one down into what happened, what it could mean for your ...
Security Education
The Browser Became the Endpoint. Your Security Stack Didn’t Notice.

An employee clicks a box that says “verify you’re human.” A prompt tells them to press a couple of keys, so they do. What they have actually done is paste and run a command that a script slipped onto their clipboard the moment they ...
Vulnerabilities Are Now the #1 Way In. The Window to Fix Them Is Closing.

Most of the time, I didn't break into a network so much as let myself in through something with a fix already out (just not installed yet): the VPN concentrator three versions behind, the firewall with a known vulnerability fixed ...
Your OSINT Reality Check: Here’s What an Attacker Is Finding in 30 Minutes or Less

Today’s connected, AI-driven digital ecosystem has made it easier than ever to build a professional brand, network with peers, and share ideas with a wider audience. It’s opened doors for businesses that simply didn't exist before: new customers, new partnerships, ...
Strategy & Leadership
An Open Letter From Your Cyber Risk Advisors

After the Water Attacks Last month, attackers reached into water treatment plants across a dozen states and started moving the controls. Some of them found out what happens when you do. I've been thinking about what to say to the ...
Building Trust in Executive Relationships: Lessons from King Lear

A Framework for Establishing the Kind of Trust that Survives Budget Season Imagine the curtain going up and a group of players act out the opening scenes of Shakespeare's King Lear, just for you. An aging king sits in his ...
Your Jokes Were Funny. They Still Didn't Renew.

How MSPs Build the Kind of Client Rapport That Survives a Budget Review You walked out of the meeting feeling good. The handshake was firm, the small talk landed, and you even got a laugh with the printer joke. You ...
All Articles
New Android Malware Steals Data And Factory Resets Phones
BRATA malware was first spotted in the wilds by Kaspersky back in 2019. Its earliest incarnation saw it targeting e-banking users and it was designed to steal banking and login credentials of ...
Suspicious Files Get New Warnings In Google Drive
If you have Google Drive, there's good news. The company has recently announced that soon they'll be rolling out a new feature to help alert users to the presence of suspicious documents. ...
High Profile Instagram Accounts Being Held For Ransom By Hackers
Hackers have recently hit upon a new money-making scheme. Some groups have started breaking into Instagram accounts belonging to people with high numbers of followers. They are then holding those accounts hostage ...
Dark Herring Subscription Scam Affected Millions Of Android Users
Google partner Zimperium zLabs has recently discovered a sophisticated scam targeting more than 100 million Android users. The scam has been in operation right under Google's nose for nearly two years. The ...
Apple Released A Fix For Multiple Zero Day Exploits
There's good news for Apple users. The company has been busy and has recently released security updates that address two Zero-Day vulnerabilities. These are security flaws that could be exploited by hackers ...
Why Security Tools Are Not Enough
You have an advanced security stack. You’re investing in what seem to be amazing shiny new tools that can do all sorts of things. Maybe your clients apricate all of what is ...
Android Apps Are Coming To Windows 11
One of the most persistently frustrating aspects of our highly interconnected world is that we seem to exist in at least three different distinct ecosystems. Apple users live in the Apple ecosystem ...
E-Mail From Department Of Labor Could Be Phishing Attack
There is a new phishing campaign to keep a watchful eye on according to email security firm INKY. It's a particularly fiendish one. The attackers have designed an email template that does ...
Vulnerability In This Cisco Software Could Allow Hackers Access
Cisco recently discovered a critical security flaw in their Cisco Redundancy Configuration Manager (RCM) for Cisco StarOS. The vulnerability allowed an attacker to execute code arbitrarily and gain root-level access on any ...
This Plugin Could Put Your WordPress Site At Risk
The WP HTML Mail plugin has been installed on more than 20,000 websites. If you've built a WordPress site for your business and you use that plugin, be aware that you are ...
Support Comes To An End For iOS 14 For iPhone Devices
When Apple first released iOS 15 they posted a promise on their website. That promise was: "If you're using iOS or iPadOS 14.5 or later, you might now see the option to ...
Top 10 Brands That Phishing Attackers Use To Scam Users
Scammers delight in impersonating government agencies and well-known brands to lure email recipients into giving up their personal information. That information is then either exploited directly or sold to the highest bidder ...


